9c945688c0
Slice 1 — the no-manifest fallback RestoreApp no longer starts the WHOLE stack at the current definition before the replay (a newer app could migrate the restored data underneath it). New order: resolve DB services from the live compose -> stop -> volumes -> DB-only start (StartStackServices, the same helper the unit restore uses, R-47) -> replay -> full start -> health wait. A dump with no identifiable DB service is refused before any mutation (same gate and message as the unit and off-site paths). A failed volume leg skips the replay. restoreDockerVolumes now goes through the existing volumeReplayFrom seam (nil in production) so the order is testable without Docker. Slice 2 — a unit restore whose volume leg failed no longer calls the importer. Everything else on that failure path is unchanged: dataErr is returned as "completed with data errors", the unit's definition is written and the app is fully started. No loader change, no new delete step. Red-proofs in felhom.eu documentation/audits/design-build-2026-10-06/B/ (red-slice1-fallback-order.txt, red-slice2-no-replay-after-volume-failure.txt). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS